Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
BID:42637
Info
Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
| Bugtraq ID: | 42637 |
| Class: | Design Error |
| CVE: |
CVE-2009-4269 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2009 12:00AM |
| Updated: | Jan 18 2011 08:11PM |
| Credit: | Apache |
| Vulnerable: |
Oracle Inform Portal 5.0 Oracle Inform Portal 4.6 Oracle Inform Portal 4.5 Apache Software Foundation Derby 10.5.3.0 Apache Software Foundation Derby 10.5.1.1 Apache Software Foundation Derby 10.4.2.0 Apache Software Foundation Derby 10.4.1.3 Apache Software Foundation Derby 10.3.3.0 Apache Software Foundation Derby 10.2.2.0 Apache Software Foundation Derby 10.2.1.6 |
| Not Vulnerable: |
Apache Software Foundation Derby 10.6.1.0 |
Discussion
Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
Apache Derby is prone to a security vulnerability due to an insecure-hashing algorithm.
Successful exploits will allows attackers to crack passwords by generating hash collisions.
Versions prior to Apache Derby 10.6.1.0 are vulnerable.
Apache Derby is prone to a security vulnerability due to an insecure-hashing algorithm.
Successful exploits will allows attackers to crack passwords by generating hash collisions.
Versions prior to Apache Derby 10.6.1.0 are vulnerable.
Exploit / POC
Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Apache Derby 'BUILTIN' Authentication Insecure Password Hashing Vulnerability
References:
References:
- Apache Derby 10.6.1.0 Release (Apache Software Foundation)
- Apache Derby Homepage (Apache Software Foundation)
- Provide a way to change the hash algorithm used by BUILTIN authentication (Apache Software Foundation)
- Oracle Critical Patch Update Advisory - January 2011 (Oracle)